Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
rlucas
on Aug 6, 2013
|
parent
|
context
|
favorite
| on:
Security advisory: Breach and Django
No, you're missing that the original GET requests can be performed in some cases over HTTP, either by forgery or by surreptitiously spoofing the user's own browser into doing it. No need to have compromised the SSL/TLS.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: